Double-Free Vulnerability in WatchGuard Fireware OS Affects VPN Processing
CVE-2026-19316

8.7HIGH

Key Information:

Vendor

Watchguard

Vendor
CVE Published:
27 August 2026

Badges

👾 Exploit Exists

What is CVE-2026-19316?

A double-free vulnerability in the WatchGuard Fireware OS iked process poses a risk where remote unauthenticated attackers can exploit this flaw by sending specially crafted network traffic. This exploitation can lead to a Denial of Service condition, disrupting VPN processing and compromising network integrity. It is crucial for affected users to review the vendor advisory and implement security updates to mitigate the risks associated with this vulnerability.

Affected Version(s)

Fireware OS Default 2025.0 < 2026.2.2

Fireware OS Default 12.0 < 12.12.2

Fireware OS Default 2026.3 < 2026.3.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

McCaulay Hudson (@_McCaulay) of watchTowr
.